• Skip to main content
  • Skip to primary sidebar
  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In
Chrome Unboxed – The Latest Chrome OS News

Chrome Unboxed - The Latest Chrome OS News

A Space for All Things Chrome, Google, and More!

  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In

Researcher hacks Google smart speaker and turns it into a wiretap and worse

December 30, 2022 By Gabriel Brangers View Comments

Support our independent tech coverage. Chrome Unboxed is written by real people, for real people—not search algorithms. Join Chrome Unboxed Plus for just $2 a month to get an ad-free experience, access to our private Discord, and more. Learn more about membership here.
START FREE TRIAL (MONTHLY)START FREE TRIAL (ANNUAL)

Earlier this week, a researcher/programmer/ethical hacker Matt Kunze released a blog post detailing a serious vulnerability in Google smart home speakers that could give hackers remote control over the devices. In his blog post, Matt details how the vulnerability was discovered and then explains in frightening details exactly how this backdoor could be used to access a wide range of commands and actions using the affected Google speaker.

The potential for attack stemmed from a vulnerability that could allow someone to add themselves to the Google Home App. From there, a hacker would have the ability to control devices connected to the account. Once connected, an attacker could utilize voice commands to activate the microphone on a given device. You can imagine how much chaos could ensue from that point. Potentially, the device could then be used to do anything that the Google speaker was capable of as it relates to any other connected devices in the home. Here are some examples of potential actions:

Xremove ads
  • Control smart home switches
  • Open smart garage doors
  • Make online purchases
  • Remotely unlock and start certain vehicles
  • Open smart locks by stealthily brute forcing the user’s PIN number

Matt turned his attention to another potential action that attackers could trigger once they gained access to the Home App. Phone calls. By setting up a routine attached to a specific device, Matt was able to trigger his Google Home Mini to call his phone at a specific time based on the routine. In the video below, you can see the routine in action. Very cool and very frightening at the same time.

Given the fact that the hack gave the attacker access to the devices microphone, Matt laid out a potential scenario in which the attacker could use a Google smart speaker to spy on a household. Essentially, giving the attacker untethered access to listen from the speaker at any time. As pointed out in his blog post, this hack would not require the attacker to have wi-fi credentials to access the device.

Featured Videos

Xremove ads
  1. Victim installs attacker’s malicious Android app.
  2. App detects a Google Home on the network via mDNS.
  3. App uses the basic LAN access it’s automatically granted to silently issue the two HTTP requests necessary to link the attacker’s account to the victim’s device (no special permissions necessary).

Matt goes on to explain, in depth, the various ways that a hacker could implement multiple nefarious attacks using this backdoor in the Home App. Thankfully, the story has a happy ending.

The Good News

As Mr. Kunze is an ethical hacker, this vulnerability was reported to Google months ago and a patch was released well before the weakness was made public. According to the timeline, the vulnerability was reported in January of 2021 and the fix was implemented in April of the same year. Not long after that, Matt was rewarded for his efforts with a whopping $107,500 bug bounty for his work in identifying this weakness. That means that you don’t have to worry about this type of attack happening as it was derailed before it ever made it out into the wild. You can read the full, in-depth report on Matt’s new blog here.

SUBSCRIBE TO UPSTREAM

Get Chrome Unboxed delivered straight to your inbox

Upstream is our flagship, curated newsletter with the top stories, most click-worthy deals, giveaways, and trending articles from Chrome Unboxed sent directly to your inbox a few times a week. Join 31,000+ subscribers.

Xremove ads
SUBSCRIBE HERE!

Filed Under: News, Privacy and Security Tagged With: videos

About Gabriel Brangers

Lover of all things coffee. Foodie for life. Passionate drummer, hobby guitar player, Web designer and proud Army Veteran. I have come to drink coffee and tell the world of all things Chrome. "Whatever you do, Carpe the heck out of that Diem" - Roman poet, Horace. Slightly paraphrased.

Primary Sidebar

Xremove ads

Deals

Massive Deal Alert: The Acer Chromebook Plus Spin 714 just hit an all-time low $499

By Robby Payne
April 1, 2026

The best Chromebook deals today

By Robby Payne
March 30, 2026

The Acer Chromebook Plus Spin 714 hits a new all-time low at $270 off

By Robby Payne
March 25, 2026

You can score $40 off Google’s battery-powered Nest Doorbell right now

By Joseph Humphrey
March 20, 2026

The touchscreen Lenovo Chromebook Slim 3 is a steal at under $200

By Robby Payne
March 16, 2026

More Deals

Xremove ads

Reviews

Acer Chromebook Plus Spin 514 Review: Kompanio Ultra power in a convertible

By Robby Payne
December 24, 2025

My review after 6 weeks with the Lenovo Chromebook Plus 14 [VIDEO]

By Robby Payne
August 11, 2025

One week with the best small Android tablet you can buy, and I’m sold

By Robby Payne
May 9, 2025

Best Chromebooks of 2024 [VIDEO]

By Robby Payne
November 28, 2024

Samsung Galaxy Chromebook Plus Review: Samsung is back! [VIDEO]

By Robby Payne
October 28, 2024

More Reviews

Xremove ads

Guides

This Chromebook trackpad shortcut is definitely not new, but is blowing my mind

By Robby Payne
March 11, 2024

How to reduce broadcast delay on YouTube TV to stop live spoilers

By Robby Payne
December 8, 2023

Windows PC keyboard and Chromebook

How to use a Windows keyboard with a Chromebook

By Joseph Humphrey
December 8, 2023

How reset and revert your Chromebook to the previous version of Chrome OS

By Robby Payne
November 29, 2023

My Chromebook Plus features disappeared: here’s how I fixed it

By Robby Payne
November 24, 2023

More Guides

TWITTER · FACEBOOK · INSTAGRAM · YOUTUBE · EMAIL · ABOUT

Copyright © 2026 · Chrome Unboxed · Chrome is a registered trademark of Google Inc.
We are participants in various affiliate advertising programs designed to provide a means for us to earn fees by linking to affiliated sites.

PRIVACY POLICY